MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted MP4 file.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HTechsmith Mp4v2
APPTechsmith2.1.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoSMemory
CWE
Referencje
Powiązane podatności
CVE-2018-14403CRITICAL9.8PL ✓ten sam produkt
MP4v2: type confusion w MP4NameFirstMatches prowadząca do out-of-bounds memory access
CVE-2018-14054CRITICAL9.8PL ✓ten sam produkt
Double free w klasie MP4StringProperty biblioteki MP4v2 2.0.0
CVE-2018-14379HIGH8.8ten sam produkt
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case wh...
CVE-2018-14325HIGH8.8ten sam produkt
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4at...
CVE-2018-14326HIGH8.8ten sam produkt
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the...